Skip to main content
← All posts·
Regulatory Compliance

DORA Compliance for CCPs & Clearing Houses: Systemic Resilience

DORA compliance for central counterparties and clearing houses. Systemic importance of CCP infrastructure, real-time risk systems resilience, EMIR interaction, critical third-party oversight, and TLPT requirements for financial market infrastructure.

Luca Berton10 min read

CCPs: Where DORA Meets Systemic Risk

Central counterparties are among the most systemically important entities in the financial system. When you buy or sell a derivative, the CCP stands between buyer and seller, guaranteeing both sides of the trade. If a CCP fails, the entire financial market seizes. Post-2008, regulators pushed more derivatives through central clearing (EMIR in the EU) — which reduced bilateral counterparty risk but concentrated risk in CCPs.

Under DORA, CCPs are classified as essential entities with the strictest requirements, including mandatory threat-led penetration testing (TLPT).

Critical CCP Systems

Real-Time Risk & Margining

  • Real-time risk engine: Continuously calculates margin requirements across millions of positions. Latency requirements: sub-millisecond. Any disruption could trigger margin calls or fail to detect exposures.
  • Margin calculation: Initial margin, variation margin, default fund contributions — all calculated multiple times daily. Errors directly affect financial stability.
  • Default management: If a clearing member defaults, the CCP must auction the defaulter's portfolio and manage losses. This process is time-critical and must work under extreme stress.
  • Settlement systems: Cash and securities settlement — must interface reliably with central securities depositories (CSDs) and payment systems (TARGET2).

Network & Connectivity

  • Clearing member connectivity: Dedicated network connections to major banks and brokers. SLA requirements: 99.99%+ availability.
  • Market data feeds: Real-time pricing for mark-to-market. Multiple source redundancy required.
  • Regulatory reporting: EMIR reporting to trade repositories. Must continue even during incidents.
  • Cross-CCP links: Interoperability agreements with other CCPs — failure propagation risk.

DORA Requirements for CCPs

Enhanced Requirements (Beyond Standard DORA)

  • TLPT mandatory: CCPs must undergo threat-led penetration testing (TIBER-EU framework) at least every 3 years. Tests must cover critical functions including real-time risk engines.
  • Recovery time objectives: 2-hour RTO for critical functions is the market standard. Some regulators expect same-day recovery for all functions.
  • Third-party concentration risk: CCPs typically depend on a small number of critical vendors — Bloomberg (market data), SWIFT (messaging), major cloud providers (if using cloud). Each is a concentration risk.
  • Board-level ICT governance: Management body must have adequate ICT expertise. Regular reporting on ICT risk posture, incidents, and testing results.
📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare

EMIR Interaction

CCPs already operate under EMIR's operational risk requirements. DORA adds and harmonises:

  • EMIR RTS on CCP resilience: Existing requirements for BCP, disaster recovery, and operational risk management. DORA doesn't replace these but adds ICT-specific requirements on top.
  • Incident reporting: DORA creates a harmonised reporting framework. CCPs previously reported to NCAs under EMIR — now also under DORA with stricter timelines.
  • Third-party oversight: DORA's Critical Third-Party Provider (CTPP) framework may designate CCP technology vendors as CTPPs — subjecting them to direct oversight by European Supervisory Authorities.
  • Proportionality: Limited for CCPs. As systemically important entities, they face the full weight of DORA requirements.
DORA
CCP
clearing houses
financial market infrastructure
EMIR
systemic risk
compliance

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →